Sign in and set up MFA
Signing in
Open your organization's portal address and enter your email and password. Tick Keep me signed in only on a device you own.
After five wrong passwords the account is locked for 15 minutes. To set a new password, use Forgot password? on the sign-in page, which emails you a link. If the link is not offered, ask an administrator for a reset link.
If your organization uses single sign-on, the sign-in page offers it once you have typed your email address, and you sign in through your identity provider.
Multi-factor authentication (MFA)
With MFA, signing in needs a six-digit code as well as your password.
Set up an authenticator app
- Open Security in the sidebar.
- Press Set up authenticator.
- Scan the QR code with any authenticator app that supports six-digit TOTP codes (Microsoft Authenticator, Google Authenticator, 1Password and similar). If you cannot scan it, choose Can't scan the code? and type the secret into the app.
- Enter the Current six-digit code from the app and press Verify and enable.
- Save your recovery codes. You get ten. Each works once, and they are never shown again. Copy or download them and keep them somewhere separate from your phone, then tick I have saved these recovery codes and press Finish setup.
From then on, after your password the portal asks for the code from your app.
When you do not have your phone
On the code screen choose:
- Use a recovery code: enter one of your unused recovery codes.
- Use email code: a code is emailed to you. If it does not arrive, press Send a new code after a minute.
- Have a sign-in pass?: enter a one-time sign-in pass from your administrator (see below).
When your organization requires MFA
An administrator can make MFA required for everyone under Organization, Sign-in policy, MFA enforcement. Until you set up an authenticator app, each sign-in sends a code to your email, and the Security page shows Required — setup needed. A required MFA cannot be turned off by the user.
One-time sign-in passes
When someone has lost their phone and their recovery codes, or an emailed code does not arrive, an administrator can give them one: under Users, open the person's actions and choose Give a one-time sign-in pass…. The pass is shown once, works once and expires after 30 minutes. The person enters it under Have a sign-in pass? on the code screen.
Every sign-in, failed attempt and pass is recorded in the Audit log.